ID

VAR-201709-1265


TITLE

SAP NetWeaver XML External Entity Injection Vulnerability

Trust: 0.3

sources: BID: 100800

DESCRIPTION

SAP NetWeaver is prone to an XML External Entity injection vulnerability. Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service conditions.

Trust: 0.3

sources: BID: 100800

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:0

Trust: 0.3

sources: BID: 100800

THREAT TYPE

network

Trust: 0.3

sources: BID: 100800

TYPE

Unknown

Trust: 0.3

sources: BID: 100800

EXTERNAL IDS

db:BIDid:100800

Trust: 0.3

sources: BID: 100800

REFERENCES

url:http://www.sap.com/

Trust: 0.3

url:https://launchpad.support.sap.com/#/notes/2492658

Trust: 0.3

url:https://blogs.sap.com/2017/11/14/sap-security-patch-day-november-2017/

Trust: 0.3

url:https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/

Trust: 0.3

sources: BID: 100800

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 100800

SOURCES

db:BIDid:100800

LAST UPDATE DATE

2022-05-17T01:57:41.015000+00:00


SOURCES UPDATE DATE

db:BIDid:100800date:2017-12-19T22:36:00

SOURCES RELEASE DATE

db:BIDid:100800date:2017-09-12T00:00:00